<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Error loading logging conf file - can't start Splunk Enterprise Server in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Error-loading-logging-conf-file-can-t-start-Splunk-Enterprise/m-p/128697#M9664</link>
    <description>&lt;P&gt;Not able to start Splunk.&lt;/P&gt;

&lt;P&gt;When running "./splunk start" from the command line,  Splunk Enterprise Server fails to start with the following error message:&lt;/P&gt;

&lt;P&gt;Error loading logging conf file='/opt/splunk/etc/log.cfg'; runContext=splunkd&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jul 2015 22:43:53 GMT</pubDate>
    <dc:creator>rdjoraev_splunk</dc:creator>
    <dc:date>2015-07-17T22:43:53Z</dc:date>
    <item>
      <title>Error loading logging conf file - can't start Splunk Enterprise Server</title>
      <link>https://community.splunk.com/t5/Installation/Error-loading-logging-conf-file-can-t-start-Splunk-Enterprise/m-p/128697#M9664</link>
      <description>&lt;P&gt;Not able to start Splunk.&lt;/P&gt;

&lt;P&gt;When running "./splunk start" from the command line,  Splunk Enterprise Server fails to start with the following error message:&lt;/P&gt;

&lt;P&gt;Error loading logging conf file='/opt/splunk/etc/log.cfg'; runContext=splunkd&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 22:43:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Error-loading-logging-conf-file-can-t-start-Splunk-Enterprise/m-p/128697#M9664</guid>
      <dc:creator>rdjoraev_splunk</dc:creator>
      <dc:date>2015-07-17T22:43:53Z</dc:date>
    </item>
    <item>
      <title>Re: Error loading logging conf file - can't start Splunk Enterprise Server</title>
      <link>https://community.splunk.com/t5/Installation/Error-loading-logging-conf-file-can-t-start-Splunk-Enterprise/m-p/128698#M9665</link>
      <description>&lt;P&gt;As per error message, root cause of the issue is related to log.cfg file in located the /opt/splunk/etc/ directory.&lt;/P&gt;

&lt;P&gt;Checked in the splunkd.log file in $SPLUNK_HOME/var/log/splunk and observed the following message in it:&lt;/P&gt;

&lt;P&gt;WARN  Logger - /opt/splunk/etc/log.cfg:11: Parse error at "TailingProcessork....&lt;/P&gt;

&lt;P&gt;It was found that the category.TailingProcessor parameter name was not spelled correctly. After updating the parameter name in the log.cfg file, user was able to start Splunk Server successfully.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 23:02:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Error-loading-logging-conf-file-can-t-start-Splunk-Enterprise/m-p/128698#M9665</guid>
      <dc:creator>rdjoraev_splunk</dc:creator>
      <dc:date>2015-07-17T23:02:03Z</dc:date>
    </item>
  </channel>
</rss>

